expression-compiler
Fail
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: CRITICALDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: The script
calculate.pycontains a functioncompile_expressionthat utilizes the Python built-incompile()function with theevalmode on theexpressionparameter. This allows for the transformation of any string into an executable Python code object at runtime. - [COMMAND_EXECUTION]: The ability to compile arbitrary strings into code objects creates a direct pathway for arbitrary code execution (ACE). If the input
expressionis sourced from untrusted data or user prompts, an attacker could inject malicious Python code—such as__import__('os').system('...')—to execute system-level commands, leading to full system compromise.
Recommendations
- AI detected serious security threats
Audit Metadata